top of page
Search

Navigating Risk in 2026: The COSO Risk Assessment

Updated: 4 days ago


In this installment of Navigating Risk in 2026, we examine the Risk Assessment component of the Committee of Sponsoring Organizations of the Treadway Commission (COSO) Enterprise Risk Management framework. Financial institutions worldwide rely on COSO to structure risk governance, align risk with strategy, and support sound decision-making across the three lines of defense.

 

A risk assessment is a structured, proactive process to identify potential threats and opportunities, evaluate their significance, and determine how to manage them effectively. Done well, it equips an organization to respond to uncertainty with clarity and speed. Done poorly—or not at all—it leaves leadership blind to key hazards, resulting in delayed, inconsistent, or costly responses.


 Steps to Performing a Risk Assessment


1.        Understand organizational goals and objectives.

2.        Identify the risks to organizational goals and objectives.

3.       Evaluate significance and prioritize risks using the Impact vs Likelihood Risk Matrix.


The Impact vs Likelihood Risk Matrix


The impact vs likelihood risk matrix is a risk assessment tool used to evaluate and prioritize risks based on their likelihood of occurrence. The matrix evaluates and prioritizes risks using two scales:


·        Likelihood Scale: “Very Unlikely” to “Very Likely”.

·       Impact Scale: “Negligible” to “Severe”.


Risks are plotted on the matrix based on the likelihood and impact of the uncertainty. The below graphic shows a typical impact vs likelihood risk matrix.


The matrix helps organizations to focus their resources on the most critical risks and plan effective responses by creating quadrants that represent different risk levels. High likelihood, high impact risks require immediate attention, while low likelihood, low impact risks can be monitored or ignored.


Ten (10) questions every financial institution should ask during the risk assessment process:

 

1.           Methods and artifacts: What sources have been used to identify the company’s goals and objectives (e.g., strategy, operating plan, regulatory mappings, internal audit, third-party reports)?


2.           Scale calibration: What values define “Negligible” through “Severe” impact, and what thresholds determine likelihood ratings? Are these definitions scaled to our business and consistently applied?


3.           Risk appetite alignment: Have Board-approved risk appetite and tolerance levels informed the construction of the likelihood and impact scales and the triggers for escalation?


4.           Governance and approval: Is there a formal process and cadence for reviewing and approving the Impact vs Likelihood Matrix at management and Board levels?


5.           Model validity: What controls ensure the matrix, and its parameters remain valid as our business, products, and risk profile evolve (e.g., back-testing, benchmarking, Key Risk Indicators (KRI) calibration)?


6.            Change management: What change controls (ownership, versioning, peer review, User Acceptance Testing (UAT), training, effective dating) protect the integrity of the model across the organization?


7.           Portfolio view and cost: What proportion of identified risks fall into the “High” quadrant, and what are the expected one-off and run-rate costs to reduce them to acceptable residual levels?


8.           Pricing and economics: Do product pricing models and Risk Adjusted Return on Capital (RAROC) (or equivalent) adequately reflect expected losses, capital charges, and the cost of risk management controls?


9.            Treatment of de minimis risks: Should risks assessed as very unlikely with minor impact be accepted and monitored, and under what trigger conditions should they be re-assessed?


10.     Assurance: What assurance will validate management’s assessment (first-line control testing, second-line independent challenge/validation, and third-line internal audit), and how will findings feed back into methodology improvements?

 

Closing Thoughts

A COSO-aligned risk assessment is more than a heatmap—it is a living, governed methodology that links strategy, data, expert judgment, and action. When scales are well-calibrated, governance is clear, and assurance loops are active, institutions can deploy capital and controls where they yield the greatest reduction in risk per dollar and respond to emerging threats with confidence.


Call us today to learn more about our risk assessment services and how we can help your organization meet its strategic and operational goals.



 
 
 

Comments


bottom of page